Skip to content
CVE-2026-44207 - Exploits & Severity

CVE-2026-44207 - Exploits & Severity

Feedly June 13, 2026

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows authenticated users to access other users' email configuration details. This issue has been patched in versions 15.107.0 and 16.17.0.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

NVD published the first details for CVE-2026-44207

A CVSS base score of 6.9 has been assigned.

Feedly found the first article mentioning CVE-2026-44207 . See article

CVE-2026-44207 | Frappe up to 15.106.x/16.16.x Configuration authorization (GHSA-cw6v-39qx-7r74)

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

Attack Types (1)

Platforms (1)